Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
443 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.93% | — | Zohocorp Manageengine Applications Manager | 29/1/2025 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function. | |
| Analizada | Media (4.7) | 2.5% | — | Zohocorp Manageengine Applications Manager | 1/8/2024 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature. | |
| Modificada | Alta (7.5) | 1.4% | 💥 PoC | KJD Internationalized Domain Names IN Applications | 7/7/2024 | 17/6/2026 | A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is… | |
| Aplazada | Media (6.2) | 0.17% | — | HP Advance Mobile ApplicationsAIApple IOSAIGoogle AndroidAI | 12/6/2024 | 17/6/2026 | HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. | |
| Analizada | Alta (8.1) | 1.6% | — | Redhat Build OF KeycloakRedhat Jboss Middleware Text-only AdvisoriesRedhat KeycloakRedhat Migration Toolkit FOR Applications+6 | 17/4/2024 | 4/8/2026 | A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that… | |
| Analizada | Media (6.5) | 0.51% | — | Oracle Applications Framework | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: REST Services). Supported versions that are affected are 12.2.9-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Analizada | Media (4.3) | 0.42% | — | Oracle WEB Applications Desktop Integrator | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: XML input). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop… | |
| Modificada | Media (5.3) | 0.54% | — | Oracle Applications Technology Stack | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Applications Technology product of Oracle E-Business Suite (component: Templates). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology. Successful… | |
| Analizada | Media (5.4) | 0.31% | — | Oracle Common Applications | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications.… | |
| Analizada | Media (6.1) | 0.33% | — | Oracle WEB Applications Desktop Integrator | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications… | |
| Modificada | Alta (7.1) | 0.95% | — | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM Z+3 | 26/1/2024 | 22/9/2026 | A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users. | |
| Modificada | Alta (7.4) | 0.32% | — | Oracle Financial Services Analytical Applications Infrastructure | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, 8.0.9, 8.1.0, 8.1.1 and 8.1.2. Easily exploitable vulnerability allows low privileged attacker with… | |
| Modificada | Media (6.1) | 0.42% | — | Spaceapplications Yacms | 20/11/2023 | 17/6/2026 | An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking. | |
| Modificada | Media (5.4) | 0.60% | — | Spaceapplications Yacms | 20/11/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the text variable scriptContainer of the ScriptViewer. | |
| Modificada | Media (5.4) | 0.60% | — | Spaceapplications Yacms | 20/11/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via crafted telecommand in the timeline view of the ArchiveBrowser. | |
| Modificada | Media (5.4) | 0.53% | — | Spaceapplications Yamcs | 19/10/2023 | 17/6/2026 | Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file containing arbitrary JavaScript and then navigate to it. Once the user opens the file, the browser will execute the arbitrary JavaScript. | |
| Modificada | Media (5.4) | 0.43% | — | Spaceapplications Yamcs | 19/10/2023 | 17/6/2026 | Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload a display referencing a malicious JavaScript file to the bucket. The user can then open the uploaded display by selecting Telemetry from the menu and… | |
| Modificada | Media (6.1) | 0.41% | — | Spaceapplications Yamcs | 19/10/2023 | 17/6/2026 | An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file. | |
| Modificada | Crítica (9.1) | 1.6% | — | Spaceapplications Yamcs | 19/10/2023 | 17/6/2026 | Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request. | |
| Modificada | Alta (7.5) | 1.0% | 💥 PoC | Spaceapplications Yamcs | 19/10/2023 | 17/6/2026 | Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 2.3% | — | Zohocorp Manageengine Applications Manager | 10/8/2023 | 17/6/2026 | Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in. | |
| Modificada | Media (6.1) | 0.42% | — | Oracle Applications Framework | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.3-12.3.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… |